CVE-2026-23890: pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin
Summary A path traversal vulnerability in pnpm's bin linking allows malicious npm packages to create executable shims or symlinks outside of nodemodules/.bin. Bin names starting with @ bypass validation, and after scope normalization, path traversal sequences like ../../ remain intact.
Details The vulnerability exists in the bin name validation and normalization logic:
1. Validation Bypass (pkg-manager/package-bins/src/index.ts)
The filter allows any bin name starting with @ to pass through without validation:
typescript .filter((commandName) => encodeURIComponent(commandName) === commandName || commandName === '' || commandName[0] === '@' // <-- Bypasses validation )
2. Incomplete Normalization (pkg-manager/package-bins/src/index.ts)
typescript function normalizeBinName (name: string): string { return name[0] === '@' ? name.slice(name.indexOf('/') + 1) : name } // Input: @scope/../../evil // Output: ../../evil <-- Path traversal preserved!
3. Exploitation (pkg-manager/link-bins/src/index.ts:288)
The normalized name is used directly in path.join() without validation.
PoC 1. Create a malicious package: json { "name": "malicious-pkg", "version": "1.0.0", "bin": { "@scope/../../.npmrc": "./malicious.js" } }
2. Install the package: bash pnpm add /path/to/malicious-pkg
3. Observe .npmrc created in project root (outside nodemodules/.bin).
Impact - All pnpm users who install npm packages - CI/CD pipelines using pnpm - Can overwrite config files, scripts, or other sensitive files
Verified on pnpm main @ commit 5a0ed1d45.
Other sources
pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's bin linking allows malicious npm packages to create executable shims or symlinks outside of nodemodules/.bin. Bin names starting with @ bypass validation, and after scope normalization, path traversal sequences like ../../ remain intact. This issue affects all pnpm users who install npm packages and CI/CD pipelines using pnpm. It can lead to overwriting config files, scripts, or other sensitive files. Version 10.28.1 contains a patch.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23890?
CVE-2026-23890 is classified as a high severity vulnerability due to its potential for arbitrary file creation.
How do I fix CVE-2026-23890?
To fix CVE-2026-23890, upgrade to pnpm version 10.28.1 or later.
What type of vulnerability is CVE-2026-23890?
CVE-2026-23890 is a path traversal vulnerability that allows the creation of executable shims or symlinks outside of the intended directory.
Which versions of pnpm are affected by CVE-2026-23890?
CVE-2026-23890 affects all versions of pnpm prior to 10.28.1.
Who is impacted by CVE-2026-23890?
Developers using vulnerable versions of pnpm for managing their Node.js packages are at risk from CVE-2026-23890.